Back to skill

Security audit

LYGO Champion: lyra starcore

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed legacy persona helper with small local reference/hash scripts and no evidence of hidden execution, exfiltration, or automatic system changes.

This is reasonable to install if you want the legacy LYRA persona or need to inspect its mint hash. Treat any linked verifier or mint/backfill workflow as a separate tool: review where it writes ledgers and confirm before using it to persist anchors or hashes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
80% confidence
Finding
The skill is presented as a deprecated persona helper, but its documented behavior includes validation of local files, parsing metadata from `references/canon.json`, checking verifier usage, and outputting a mint hash. This mismatch can mislead users and reviewers about the actual data-access and verification behavior, increasing the risk of unintended disclosure of local package metadata or trust abuse through opaque verification claims.

Missing User Warnings

Low
Confidence
91% confidence
Finding
The instructions explicitly describe writing append-only and canonical ledgers, but they do not warn users that local files or state may be modified. In an agent setting, undocumented write behavior can cause unintended persistence, overwrite assumptions, or user surprise, especially when the skill description does not signal filesystem-affecting actions.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.